Are they listening?

Privacy policy

Are they listening?, by Headway Tech LLC. Last updated October 8, 2026.

The short version. There's no account, no advertising and no analytics. Detection happens on your phone. Three things leave it, each only when you use that feature: the VPN carries your traffic through our server, which keeps no logs; the email leak check sends the address you type to Have I Been Pwned; and the lists the app downloads (scam numbers, ad and scam sites, satellite orbits, the road map) are the same public files for everyone. Nothing about your texts, calls, browsing, scans or location is sent to us.

What the app does on your phone

Are they listening? looks for devices near you that can hear, see or track you, and explains what each one does. It listens to what devices broadcast on their own over Bluetooth, briefly connects to Bluetooth devices it can't name to read what they call themselves, and asks devices on the Wi-Fi you have joined to identify themselves. It doesn't pair with, record from or take control of anything it finds. The one thing it ever sends a device is a ring command, and only when you tap Make it beep on a tracker that may be following you.

What we collect

Nothing, unless you turn on the VPN: Headway Tech LLC does not collect or receive personal information, and we can't see your scans, your location, your routes, your texts, your calls, the sites you visit or the devices around you. What the VPN keeps is listed below, and it isn't about what you do. The outside services a feature asks, and exactly what each receives, are in the table further down.

The VPN

The VPN is off until you turn it on. When it's on, your iPhone's internet traffic goes, encrypted, from your iPhone to our server, run by Headway Tech LLC at OVHcloud in Oregon, USA, and from there to the internet. The Wi-Fi you're on sees only that you're connected to our server, not the sites and apps you use.

What our server keeps, for each iPhone that turns it on: a random ID, a hashed copy of a token only that iPhone holds (so only it can change or remove its record), whether it blocks ads and trackers, the day it was added, and its VPN key so it can connect. That's all. We use it only to run the VPN, and we don't sell it, use it for any other purpose, or disclose it to anyone else.

What it doesn't keep: the sites or apps you use, your traffic, your DNS lookups, your IP address, or when you connect and disconnect. The VPN service, the DNS resolver, the firewall and the web server on it are set up to write none of this, and we check that they don't. While you're connected, the server holds in memory only what it needs to send your traffic back to you; it's gone when you disconnect.

Blocking: its DNS resolver blocks known malware, phishing and scam sites for everyone, and ads and trackers unless you turn that off, using HaGeZi's public blocklists. It doesn't record what it blocks.

Who else is involved: OVHcloud runs the data center and network our server is in, and carries traffic to and from it as any internet provider does. The server's name, vpn-west.headwaytech.app, is published through Cloudflare's DNS.

Removing it: Remove the VPN from this iPhone (VPN, Details) deletes its key from your iPhone and its record from our server. Deleting the app also takes the VPN off your iPhone.

Legal requests: we answer valid legal process as the law requires. Because the server keeps no logs, we generally have nothing about your activity to give.

What it isn't: it hides your activity from the Wi-Fi network, not from sites you sign in to, and it doesn't make you anonymous. It can't stop cameras or microphones in a room; the scan is for those.

Scams, calls, texts and Safari

Web Protection and the Ad Blocker are Safari content blockers. Safari does the blocking itself from a list the app gives it; the app never sees which pages you open, and neither does Safari tell it. The lists are built from public sources (named in the app under What it can and can't see) and downloaded from our site; the download carries nothing about you.

Call protection is an iOS call directory: the app hands iOS a list of numbers reported to the FTC's Do Not Call registry, and iOS labels or, if you chose, blocks calls from them. The app never sees your calls or your contacts. The list is downloaded from our site once a day.

The text filter runs inside iOS on your phone, on texts from numbers not in your contacts. Nothing from a text leaves the phone. iOS doesn't tell the app whether the filter is on; the app remembers only what you told it.

Is this text a scam? reads the text you paste, or the screenshot you pick, on the phone. The screenshot's text is read by iOS on the phone, and nothing is saved. On an iPhone with Apple Intelligence, Apple's on-device model reads it too, on the phone. A sender's number is checked against the FTC list on the phone. "Report to your carrier" opens a text to 7726 for you to send; "Report to the FTC" opens the FTC's site.

Was your email leaked? sends the address you type to our server, which passes it to Have I Been Pwned with our key and passes the answer back. Neither keeps the address or logs the request. Have I Been Pwned sees the address, as that is the check. If you keep the address, it stays on your phone and the check runs again weekly.

Was a password leaked? sends only the first five characters of a scrambled version of the password to Have I Been Pwned, which answers with every scrambled password that starts the same way. The password itself never leaves the phone.

Outside services, and what each one receives

These are used only when you use the feature named, and only for that feature.

ServiceWhenWhat it receives
Apple MapsAny map in the app; searching for a place in Plate readers or drive mode, as you type; planning a routeThe area of the map on screen, what you type as you type it, and the start and destination of a route, as in Apple's own Maps app. Governed by Apple's privacy policy.
adsb.lolOverhead, while that screen is openYour location rounded to about 1 km (0.6 mi), every 20 seconds, to get the aircraft nearby, and for a wider circle every few minutes (every 15 seconds while the sky camera is open) for the GPS check and the camera view.
Satellite orbit lists (sky.headwaytech.app, served by Cloudflare; CelesTrak if ours doesn't answer)Overhead, once a place is set, at most twice a dayNothing about you: it's the same public file for everyone, and your IP address as with any internet request. Which satellites and planets are over you is worked out on the phone; your location isn't sent. We keep no record of downloads.
OpenStreetMap (Nominatim)Overhead, when you type a placeThe place or address you typed.
OpenStreetMap (Overpass)Plate readers, when you tap "Check the live map"The location being checked, once. The plate reader map is otherwise built into the app, so looking up readers near you doesn't leave the phone.
Our road map (roads.headwaytech.app, served by Cloudflare)Plate readers: when the map first opens near you, and when a route goes through an area the phone doesn't have yetWhich squares of the road map the phone needs, each about 28 by 21 km (17 by 13 mi), and your IP address as with any internet request. Never your start, destination or route: routes past no plate readers are worked out on the phone. We keep no record of downloads.
Cloudflare speed test (speed.cloudflare.com)Who's on my Wi-Fi, Internet: when you tap Run speed testTest data downloaded and uploaded (up to about 200 MB), and your IP address as with any internet request, which it uses to name your provider and city. Nothing else.
Cloudflare (1.1.1.1) and Shodan InternetDB (internetdb.shodan.io)Who's on my Wi-Fi, Security: when you tap Check what's exposedCloudflare is asked for this connection's internet address, and that address is looked up in Shodan's InternetDB, a public record of what its scans of the internet found open there. Nothing else.
Public DNS services: Cloudflare (1.1.1.1), Google (8.8.8.8) and Quad9 (9.9.9.9)Who's on my Wi-Fi, Internet: when you tap Compare DNS speed. DNS lookup in Tools asks Cloudflare only when the app doesn't know your routerLookups of five well-known names (apple.com, google.com, wikipedia.org, amazon.com and cloudflare.com), or the name you typed into DNS lookup, and your IP address, as with any DNS lookup.
Have I Been Pwned, through our server (headwaytech.app, served by Cloudflare)Was your email leaked?: when you check an address, and weekly for an address you keepThe email address, passed on once and not kept by us. Have I Been Pwned's own policy covers what it does with it.
Have I Been PwnedWas a password leaked?: when you check a passwordThe first five characters of the password's hash. Never the password.
Our lists (headwaytech.app, served by Cloudflare)Scam numbers, once a day; the ad and tracker list, once a week; the Safari self-test page when you open itNothing about you: the same public files for everyone, and your IP address as with any internet request.
Quad9 (dns.quad9.net, a Swiss nonprofit resolver)Block in every app, while it is on (from app 1.11.0)The names of the sites your apps look up, encrypted on the way, the way your internet provider's resolver sees them otherwise. Blocked names never leave the phone. Nothing is sent to us; the filter runs on the phone and keeps two counts there (lookups checked, lookups blocked), no names. Quad9's own policy says it keeps no logs of who asked.
Apple (on this phone)Is this text a scam?, on an iPhone with Apple IntelligenceNothing leaves the phone: Apple's on-device model runs here. Apple's own Apple Intelligence terms apply.
RevenueCatWhen the app starts, to check whether you own the unlock or a plan for it and get the prices, and when you buy, restore or manage itAn anonymous purchase ID, the purchase record from Apple, and the device model and app version. No name or email.
ExpoWhen the app checks for an updateThe app version and platform, and your IP address as with any internet request.
Waze, Google Maps, Apple MapsWhen you choose "Open in" one of them on the plate-reader mapThe destination you picked, and for a route past fewer cameras a few points along it, are passed to that app, which then works under its own policy.

The live map check goes to one of three public Overpass servers: overpass-api.de, overpass.kumi.systems or overpass.private.coffee.

Links you open to other sites, such as an aircraft's flight track, the FAA registry or DeFlock, open in your browser under those sites' policies.

Permissions, and why

What stays on your phone

The app keeps only what you would want to find again, only on the phone, and deletes it on these schedules:

"Forget everything" in Settings clears all of it at once, the kept email address included, except the devices you marked as yours, your settings and the last error message, which each have their own place in Settings. Deleting the app removes everything.

Sharing

When you share a report, a log or a spot, the app hands it to your phone's share sheet. Where it goes from there is your choice; the app never sends it anywhere itself.

Children

The app isn't directed at children under 13, and we don't knowingly collect personal information from them.

This website

headwaytech.app counts its visitors with Cloudflare Web Analytics, which sets no cookies and doesn't follow you across sites. We see totals only, such as page views and the countries they came from. The app itself has no analytics.

Changes

If this policy changes, the new version will be posted here with a new date.

Contact

Headway Tech LLC · [email protected]